About ClawHub
The Official OpenClaw Skill Registry - "npm for AI Agents"
Run Your OpenClaw Agent 24/7
Stop managing servers. Let us host your OpenClaw agent with automatic updates, real-time monitoring, and instant scaling across all major messaging platforms.
What is ClawHub?
ClawHub is the official, centralized skill registry for OpenClaw, serving as the "npm for AI agents." Created and maintained by the OpenClaw project team led by Peter Steinberger, ClawHub hosts 3,286 community-built skills that extend OpenClaw agent functionality.
ClawHub provides a fast, searchable platform for discovering, installing, and managing OpenClaw skills with advanced vector search technology, semantic versioning, and robust community features.
🎯 Core Mission
ClawHub aims to be a centralized hub for discovering, installing, and managing OpenClaw skills, making it easy for developers and users to extend their AI agents with reusable capabilities.
Key Statistics (February 2026)
How ClawHub Works
Skill Structure
Each ClawHub skill is a versioned file package containing:
- SKILL.md file: Defines metadata, interface, and execution logic
- Metadata: name, version, description, and dependencies
- Interface Definition: Clear instructions for AI tool calling
- Execution Logic: Actual scripts (Python, Node.js, or Bash)
Core Features
1. Vector Search Technology
ClawHub uses embeddings-based semantic search instead of simple keyword matching. This means you can search using natural language descriptions, and ClawHub will find relevant skills even if they don't contain your exact keywords.
openclaw skill search "automate my email workflow"
# Finds email automation skills even without exact match
2. Semantic Versioning (Semver)
ClawHub follows semantic versioning for all skills:
- MAJOR.MINOR.PATCH (e.g., 1.2.3)
- Each version is immutable and downloadable
- Tags like "latest" point to specific versions
- Changelogs document all changes
3. CLI Integration
ClawHub provides CLI-friendly API for seamless integration:
openclaw skill install github-integration
# Install specific version
openclaw skill install [email protected]
# Update skills
openclaw skill update github-integration
# List installed skills
openclaw skill list
4. Community Features
- Stars: Community rating system
- Comments: User feedback and reviews
- Reporting System: 3 independent reports auto-hide suspicious skills
- Moderation: Review team can restore, delete, or ban users
ClawHub vs npm
ClawHub is often called the "npm for AI agents" because it follows a similar architecture:
However, ClawHub is specifically designed for AI agent skills with unique features like vector search and natural language skill discovery.
ClawHavoc Security Incident
⚠️ Critical Security Event - February 2026
In February 2026, security researchers discovered 341 malicious skills on ClawHub that were stealing OpenClaw user data. This incident, codenamed "ClawHavoc", highlighted important security challenges in open AI agent ecosystems.
Timeline of Events
Attack Details
- Malware Type: Atomic Stealer (credential theft trojan)
- Target Platforms: macOS and Windows
- Attack Method: Fake prerequisites tricking users into downloading malware
- Stolen Data: Credentials, crypto wallets, and sensitive information
Root Cause
ClawHub's open-by-default architecture allowed anyone with a GitHub account (at least one week old) to upload skills. This low barrier enabled malicious actors to publish harmful skills at scale.
OpenClaw Team Response
Peter Steinberger and the OpenClaw team implemented several security improvements:
- ✅ Enhanced reporting functionality
- ✅ Automatic skill hiding after 3 independent reports
- ✅ Automated malware scanning for all submissions
- ✅ Stricter skill review processes
- ✅ Strengthened community moderation
- ✅ Real-time security monitoring
Media Coverage
The ClawHavoc incident received widespread coverage:
- The Hacker News: "Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users"
- SC Media: "OpenClaw agents targeted with 341 malicious ClawHub skills"
- VirusTotal Blog: "From Automation to Infection: How OpenClaw AI Agent Skills Are Being Weaponized"
- Koi.ai: "ClawHavoc: 341 Malicious Clawed Skills Found by the Bot They Were Targeting"
- CrowdStrike: "What Security Teams Need to Know About OpenClaw, the AI Super Agent"
Learn more: Visit our comprehensive Security Guide for detailed information and protection measures.
Official ClawHub Resources
Community Resources
- Awesome OpenClaw Skills: github.com/VoltAgent/awesome-openclaw-skills - Curated collection of high-quality skills
- OpenClaw Hub: openclaw-hub.com - Community guides and user showcases
- OpenClaw Discord: Community support and discussions
⚠️ About ClawHub.biz
ClawHub.biz is an independent information portal and is NOT officially affiliated with OpenClaw or ClawHub.
Purpose: This website was created to provide comprehensive, user-friendly information about ClawHub and help users safely navigate the ecosystem, especially after the ClawHavoc security incident.
For official information, always visit:
- Official ClawHub: https://clawhub.ai
- Official OpenClaw: https://openclaw.com
- Official Documentation: https://docs.openclaw.ai/tools/clawhub
Contact: For questions about this website, please refer to our About page.